Is it an easy way to list IP's from different columns into one? For instance,
header ip1 ip2 ip3
------- ------- -------- --------
record1 1.1.1.1 2.2.2.2 3.3.3.3
record2 4.4.4.4 5.5.5.5 6.6.6.6
The end result looks like the following:
header ip
---------- -----------
record1 1.1.1.1
2.2.2.2
3.3.3.3
record2 4.4.4.4
5.5.5.5
6.6.6.6
Here is my search query:
| makeresults
| eval header="record1", ip1="1.1.1.1", ip2="2.2.2.2", ip3="3.3.3.3"
| append [| makeresults | eval header="record2", ip1="4.4.4.4", ip2="5.5.5.5", ip3="6.6.6.6"]
| fields - _time
| eval ip=ip1+"|" + ip2+"|"+ip3
| fields - ip1 ip2 ip3
| makemv delim="|" ip
It works as expected, but it seems cumbersome. Is there a better way to achieve the same result? Thanks.
... View more